Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2748▲ 37 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.24% | — | Parla Auto Automotive Trading Limited Company Detawix Mobile WEB PortalAI | 29/9/2026 | 30/9/2026 | Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Limited Company DetaWix Mobile Web Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects DetaWix Mobile Web Portal: before v1.0.19. | |
| Pendiente de análisis | Media (5.6) | 0.25% | — | Checkpoint DLPAICheckpoint Usercheck WEB PortalAI | 26/5/2026 | 24/7/2026 | When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access the UserCheck Ask page could attempt to manipulate the Security Gateway's stored DLP/UserCheck incident information. This could lead to disruptions such as… | |
| Analizada | Baja (2.1) | 0.47% | — | Carmelo Student WEB Portal | 8/3/2026 | 17/6/2026 | A vulnerability was found in code-projects Student Web Portal 1.0. Affected is an unknown function of the file profile.php. The manipulation of the argument User results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.58% | — | Carmelo Student WEB Portal | 8/3/2026 | 17/6/2026 | A vulnerability has been found in code-projects Student Web Portal 1.0. This impacts the function valreg_passwdation of the file signup.php. The manipulation of the argument reg_passwd leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (6.9) | 0.39% | — | Carmelo Student WEB Portal | 8/2/2026 | 17/6/2026 | A vulnerability was detected in code-projects Student Web Portal 1.0. This impacts an unknown function of the file /check_user.php. Performing a manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely. | |
| Aplazada | Alta (8.6) | 0.45% | — | Saysis Computer Systems Trade LTD CO Saysis WEB PortalAI | 25/9/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saysis Computer Systems Trade Ltd. Co. Saysis Web Portal allows Path Traversal. This issue affects Saysis Web Portal: from 3.1.9 & 3.2.0 before 3.2.1. | |
| Aplazada | Crítica (9.3) | 0.29% | — | Pixmeo Osirix MD WEB PortalAI | 8/5/2025 | 17/6/2026 | The Pixmeo Osirix MD Web Portal sends credential information without encryption, which could allow an attacker to steal credentials. | |
| Aplazada | Alta (7.5) | 0.40% | — | Priority WEB Portal Add-onAI | 30/7/2024 | 17/6/2026 | Priority PRI WEB Portal Add-On for Priority ERP on prem - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | |
| Modificada | Media (5.4) | 0.76% | — | Webport WEB Port | 24/6/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerabililty in WebPort <=1.19.1 via the description parameter to script/listcalls. | |
| Modificada | Media (5.3) | 1.7% | — | Webport WEB Port | 24/6/2021 | 17/6/2026 | Directory Traversal vulnerability in WebPort <=1.19.1 in tags of system settings. | |
| Modificada | Media (5.4) | 0.73% | — | Webport WEB Port | 24/6/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in WebPort <=1.19.1via the connection name parameter in type-conn. | |
| Modificada | Media (5.4) | 0.56% | — | Webport WEB Port | 26/8/2020 | 17/6/2026 | WebPort-v1.19.17121 is affected by Cross Site Scripting (XSS) on the "connections" feature. | |
| Modificada | Media (6.1) | 9.9% | — | Webport WEB Port | 30/5/2019 | 17/6/2026 | Web Port 1.19.1 allows XSS via the /log type parameter. | |
| Modificada | Media (6.1) | 3.8% | — | Webport WEB Port | 30/5/2019 | 17/6/2026 | Web Port 1.19.1 allows XSS via the /access/setup type parameter. | |
| Modificada | Alta (7.5) | 5.3% | — | CA Erwin WEB Portal | 4/4/2014 | 17/6/2026 | Multiple directory traversal vulnerabilities in CA ERwin Web Portal 9.5 allow remote attackers to obtain sensitive information, bypass intended access restrictions, cause a denial of service, or possibly execute arbitrary code via unspecified vectors. | |
| Modificada | Media (4.3) | 1.6% | — | Simhl Sths V2 WEB Portal | 21/2/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in STHS v2 Web Portal 2.2 allow remote attackers to inject arbitrary web script or HTML via the team parameter to (1) prospects.php, (2) prospect.php, or (3) team.php. | |
| Modificada | Media (5) | 1.6% | — | Comscripts WEB Server Creator WEB Portal | 25/3/2010 | 16/6/2026 | Directory traversal vulnerability in news/include/customize.php in Web Server Creator - Web Portal 0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the l parameter. | |
| Modificada | Alta (7.5) | 3.0% | — | Comscripts WEB Server Creator WEB Portal | 25/3/2010 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) pg parameter to index.php and the (2) path parameter to news/form.php. | |
| Modificada | Media (4.3) | 1.4% | — | Comscripts WEB Server Creator WEB Portal | 25/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the forum page in Web Server Creator - Web Portal 0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to index.php. | |
| Modificada | Alta (7.5) | 2.3% | — | Comscripts WEB Server Creator WEB Portal | 30/3/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in news/include/createdb.php in Web Server Creator Web Portal 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the langfile parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (10) | 4.0% | — | Sportspanel Sports Clubs WEB Portal | 16/10/2008 | 16/6/2026 | Directory traversal vulnerability in index.php in Sports Clubs Web Panel 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter. | |
| Modificada | Alta (7.5) | 1.0% | — | Aspindir Munzursoft WEB Portal W3 | 15/10/2008 | 16/6/2026 | SQL injection vulnerability in kategori.asp in MunzurSoft Wep Portal W3 allows remote attackers to execute arbitrary SQL commands via the kat parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Jportal WEB Portal | 15/11/2007 | 16/6/2026 | SQL injection vulnerability in mailer.php in JPortal 2 allows remote attackers to execute arbitrary SQL commands via the to parameter. | |
| Modificada | Alta (7.5) | 0.99% | — | Jportal WEB Portal | 15/11/2007 | 16/6/2026 | SQL injection vulnerability in articles.php in JPortal 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter. | |
| Modificada | Alta (7.5) | 0.97% | — | Jportal WEB Portal | 10/11/2007 | 16/6/2026 | SQL injection vulnerability in mailer.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the to parameter. |